Ransom Trojan

About “Trojan-Ransom.Win32.Blocker.lajl” infection

Malware Removal

The Trojan-Ransom.Win32.Blocker.lajl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.lajl virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bitcodestudios.com

How to determine Trojan-Ransom.Win32.Blocker.lajl?


File Info:

crc32: AF8CD25F
md5: bb2c8981a9fc617ef303d60f567269ea
name: BB2C8981A9FC617EF303D60F567269EA.mlw
sha1: 6049c6603d7abe8cad2160810bb08259e03ff06e
sha256: a2d19aee74d895af291322e211930cc6643c1d867a29b9683f2df558564ad4ce
sha512: d9351d21a3d298c28a5797b1230e9a50303f166886433a44ee1d961bd2b55f4a1e6262ca08c0f7f56c7e41b7fc2f655f6c3472dfae2855a3815cf46d9ab12fe3
ssdeep: 192:N/q//T8mpvlXJiR3i/fQOLL9A/ckU6w5gWKCWKAwnW7:fMg3WfQ0L9A/cP5FL7fnW7
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright Microsoftxa9 2018
Assembly Version: 1.0.0.0
InternalName: Windows32.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: Windows32
ProductVersion: 1.0.0.0
FileDescription: Windows32
OriginalFilename: Windows32.exe

Trojan-Ransom.Win32.Blocker.lajl also known as:

K7AntiVirusTrojan ( 005318051 )
DrWebTrojan.DownLoader26.65463
ALYacGen:Variant.Bulz.371521
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.40237
SangforTrojan.Win32.Save.a
K7GWTrojan ( 005318051 )
Cybereasonmalicious.1a9fc6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Small.FA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.lajl
BitDefenderGen:Variant.Bulz.371521
NANO-AntivirusTrojan.Win32.Blocker.fcddrk
MicroWorld-eScanGen:Variant.Bulz.371521
TencentWin32.Trojan.Blocker.Pfjg
Ad-AwareGen:Variant.Bulz.371521
SophosMal/Generic-S
ComodoMalware@#3parm7s62269p
BitDefenderThetaGen:NN.ZemsilF.34692.am0@auXxa@
McAfee-GW-EditionGenericRXFK-UM!BB2C8981A9FC
FireEyeGeneric.mg.bb2c8981a9fc617e
EmsisoftGen:Variant.Bulz.371521 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Bulz.371521
McAfeeGenericRXFK-UM!BB2C8981A9FC
MAXmalware (ai score=94)
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!tff7Rkr1HXU
IkarusTrojan.MSIL.Small
FortinetMSIL/Small.FA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.lajl?

Trojan-Ransom.Win32.Blocker.lajl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment